Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=actionfraud.co.uk
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 06, 2026
Valid Until
September 04, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
92:5E:13:98:34:2B:74:C3:7E:D7:D5:6D:5A:CE:1E:5A:1E:B0:67:B3:38:1B:FA:99:86:E9:E6:8E:CC:52:BE:3B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
restobuilder.com
*.restobuilder.com
3sggqv.xyz
*.3sggqv.xyz
6kukqk.top
*.6kukqk.top
967805.cc
*.967805.cc
actionfraud.co.uk
*.actionfraud.co.uk
*.alert.actionfraud.co.uk
*.campaignstool.actionfraud.co.uk
*.mailin.actionfraud.co.uk
*.sitemap.actionfraud.co.uk
*.www.actionfraud.co.uk
bwava.com
*.bwava.com
*.pay.bwava.com
callposters.com
*.callposters.com
careinthecountryside.net
*.careinthecountryside.net
dax69game.sbs
*.dax69game.sbs
debtfixer.click
*.debtfixer.click
hbslw.com
*.hbslw.com
ikzwe.my
*.ikzwe.my
inpostzwrotomat.com
*.inpostzwrotomat.com
iraqmovie.com
*.iraqmovie.com
k46.my
*.k46.my
kregistry.com
*.kregistry.com
marineridge.world
*.marineridge.world
*.32.maturetubesexvideo.com
maturetubesexvideo.com
*.maturetubesexvideo.com
meapp-icontco.shop
*.meapp-icontco.shop
*.32.moneyclaims.online
moneyclaims.online
*.moneyclaims.online
nsulpc.com
*.nsulpc.com
ognou7.xyz
*.ognou7.xyz
phoneins.com
*.phoneins.com
propwodwide.com
*.propwodwide.com
rapidtrans.org
*.rapidtrans.org
*.backup.refi.wtf
*.m.refi.wtf
*.mail.refi.wtf
*.marketing.refi.wtf
*.qa.refi.wtf
refi.wtf
*.refi.wtf
*.secure.refi.wtf
*.stg.refi.wtf
*.web.refi.wtf
rentcoronadelmar.com
*.rentcoronadelmar.com
rieke.xyz
*.rieke.xyz
sparepart.autos
*.sparepart.autos
spencerrafael.com
*.spencerrafael.com
twjay.com
*.twjay.com
usinademusica.com
*.usinademusica.com
weddingupliftexperts.beauty
*.weddingupliftexperts.beauty
yeyhyg.gdn
*.yeyhyg.gdn
ytopjga.one
*.ytopjga.one
zzz3972.top
*.zzz3972.top
Other domains in certificate